Kaspersky Blocks 5.4 Million Web-Based Cyberattacks in UAE in H1 2026 as AI-Driven Threats Rise
DUBAI — Global cybersecurity firm Kaspersky blocked approximately 5.4 million web-based cyberattacks targeting users in the United Arab Emirates during the first half of 2026, as threat actors increasingly leverage generative artificial intelligence to accelerate and refine malicious operations.
The telemetry data was presented by Kaspersky's Global Research and Analysis Team (GReAT) during the company's annual Cyber Security Weekend conference for the Middle East, Türkiye, and Africa (META) region. Across the broader region, Türkiye recorded the highest proportion of web-threatened users (22.8%), followed by Kenya (21.2%) and Qatar (19.3%), while Saudi Arabia, Jordan, and Pakistan maintained lower targeting percentages.
Cybersecurity researchers warned that artificial intelligence has become a core operational multiplier for threat actors—scaling phishing campaign generation, automating target reconnaissance, and accelerating malware development. Large Language Models (LLMs) are now capable of generating structural code bases and execution modules, significantly reducing the financial and temporal resources required to launch new exploits. Kaspersky highlighted recent campaigns, including the FunkSec group’s deployment of Rust-based data theft tools and the RevengeHotels operations, where LLMs generated infection chains and payload delivery scripts.
"We expect artificial intelligence to remain a dominant factor shaping the threat landscape in 2026," Sergey Lozhkin, Head of GReAT for APAC, META, and Türkiye at Kaspersky, said. "AI lowers the cost and effort to adapt malicious tools, allowing threat actors to evolve tactics at an unprecedented pace. Defensive teams must prepare for faster operational shifts from attackers."
The report also cautioned against emerging risks surrounding autonomous AI Agents and compromised AI Skills. With organizations granting AI agents broad system execution privileges, a single compromised agent or extension can allow attackers to alter instruction sets, execute unauthorized internal actions, and establish persistent, long-term access within corporate networks.
To counter AI-driven threats, Kaspersky advised enterprises to enforce continuous vulnerability patching, implement advanced threat intelligence capabilities, and deploy endpoint detection and response (EDR) platforms like Kaspersky Next.
